OWASP Top 10

drpepper.txt

0

www-data

/usr/sbin/nologin

18.04.4

Dr Pepper

fe86079416a21a3c99937fea8874b667

d9ac0f7db4fda460ac3edeb75d75e16e

/assets

webapp.db

6eea9b7ef19179a06954edd0f6c05ceb

What is the admin's plaintext password? 

qwertyuiop

THM{Yzc2YjdkMjE5N2VjMzNhOTE3NjdiMjdl}

Extensible Markup Language

no

yes

XML prolog

!ELEMENT

!DOCTYPE

!ENTITY

falcon

/home/falcon/.ssh/id_rsa

MIIEogIBAAKCAQEA7

flag{fivefourthree}

thm{4b9513968fd564a87b28aa1f9d672e17}

ThereIsMoreToXSSThanYouThink

ReflectiveXss4TheWin

Then add a comment and see if you can insert some of your own HTML.

HTML_T4gs

W3LL_D0N3_LVL2

websites_can_be_easily_defaced_with_xss

The Apache Software Foundation

Denial of Service

A) A State
B) A Behaviour 

A Behaviour

Binary

webapp.com/login

HTTPS

THM{good_old_base64_huh}

THM{heres_the_admin_flag}

4a69a7ff9fd68

1611

49.99.13.16

Brute Force